CVE-2018-12911

WebKitGTK+ 2.20.3 has an off-by-one error, with a resultant out-of-bounds write, in the get_simple_globs functions in ThirdParty/xdgmime/src/xdgmimecache.c and ThirdParty/xdgmime/src/xdgmimeglob.c.
References
Link Resource
https://trac.webkit.org/changeset/233404/webkit Patch Vendor Advisory
https://usn.ubuntu.com/3743-1/ Third Party Advisory
https://trac.webkit.org/changeset/233404/webkit Patch Vendor Advisory
https://usn.ubuntu.com/3743-1/ Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:webkitgtk:webkitgtk\+:2.20.3:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*

History

21 Nov 2024, 03:46

Type Values Removed Values Added
References () https://trac.webkit.org/changeset/233404/webkit - Patch, Vendor Advisory () https://trac.webkit.org/changeset/233404/webkit - Patch, Vendor Advisory
References () https://usn.ubuntu.com/3743-1/ - Third Party Advisory () https://usn.ubuntu.com/3743-1/ - Third Party Advisory

Information

Published : 2018-07-19 13:29

Updated : 2024-11-21 03:46


NVD link : CVE-2018-12911

Mitre link : CVE-2018-12911

CVE.ORG link : CVE-2018-12911


JSON object : View

Products Affected

webkitgtk

  • webkitgtk\+

canonical

  • ubuntu_linux
CWE
CWE-787

Out-of-bounds Write